VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manual do Utilizador Página 28

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 27
vShield Administration Guide
28 VMware, Inc.
Default Rules
Bydefault,ZonesFirewallenforcesasetofrulesallowingtraffictopassthroughallvShieldZonesinstances.
TheserulesappearintheDefaultRulessectionoftheZonesFirewalltable.Thedefaultrulescannotbedeleted
oraddedto.However,youcanchangetheActionelementofeachrulefrom
AllowtoDeny.
Layer 4 Rules and Layer 2/Layer 3 Rules
ZonesFirew allofferstwosetsofconfigurablerules:L4(Layer4)rulesandL2/L3(Layer2/Layer3)rules.Layers
refertolayersoftheOpenSystemsInterconnection(OSI)ReferenceModel.
Layer4rulesgovernTCPandUDPtransportofLayer7,orapplicationspecific,traffic.Layer2/Layer3rules
monitortraffic
fromICMP,ARP,andotherLayer2andLayer3protocols.YoucanconfigureLayer2/Layer 3
rulesatthedatacenterlevelonly.Bydefault,allLayer4andLayer2/Layer3trafficisallowedtopass.
Hierarchy of Zones Firewall Rules
EachvShieldZonesinstanceenforcesZonesFirewallrulesintoptobottomordering.AvShieldZones
instancecheckseachtrafficsessionagainstthetopruleintheZonesFirewalltablebeforemovingdownthe
subsequentrulesinthetable.Thefirstruleinthetablethatmatchesthetrafficparametersis
enforced.
ZonesFirewallrulesareenforcedinthefollowinghierarchy:
1 DataCenterHighPrecedenceRules
2 ClusterLevelRules
3 DataCenterLowPrecedenceRules(seenasRulesbelowthislevelhavelowerprecedencethancluster
levelruleswhenadatacenterresourceisselected)
4 SecurePortGroupRules
5 DefaultRules
ZonesFirewalloffers
containerlevelandcustompriorityprecedenceconfigurations:
Containerlevelprecedencereferstorecognizingthedatacenterlev elasbeinghigherinprioritythanthe
clusterlevel.Whenaruleisconfiguredatthedatacenterlevel,theruleisinheritedbyallclustersand
vShieldagentstherein.AclusterlevelruleisonlyappliedtothevShieldZonesinstanceswithin
the
cluster.
Custompriorityprecedencereferstotheoptionofassigninghighorlowprecedencetorulesatthe
datacenterlevel.Highprecedencerulesworkasnotedinthecontainerlevelprecedencedescription.Low
precedencerulesincludetheDefaultRulesandtheconfigurationofDataCenterLowPrecedencerules.
Thisflexibilityallowsyou
torecognizemultiplelayersofappliedprecedence.
Attheclusterlevel,youconfigurerulesthatapplytoallvShieldZonesinstanceswithinthecluster.
BecauseDataCenterHighPrecedenceRulesareaboveClusterLevelRules,ensureyourClusterLevel
RulesarenotinconflictwithDataCenterHighPrecedenceRules.
Planning Zones Firewall Rule Enforcement
UsingZonesFirewall,youcanconfigureallowanddenyrulesbasedonyournetworkpolicy.Thefollowing
examplesrepresenttwocommonfirewallpolicies:
Allowalltrafficbydefault.YoukeepthedefaultallowallrulesandadddenyrulesbasedonFlow
MonitoringdataormanualAppFirewallconfiguration.Inthisscenario,ifasessiondoesnotmatchany
ofthedenyrules,thevShieldAppallowsthetraffictopass.
Denyalltrafficbydefault.YoucanchangetheActionstatusofthedefaultrulesfromAllowtoDeny,and
addallowrulesexplicitlyforspecificsystemsandapplications.Inthisscenario,ifasessiondoesnot
matchanyoftheallowrules,thevShieldAppdropsthesessionbeforeit
reachesitsdestination.Ifyou
changeallofthedefaultrulestodenyanytraffic,thevShieldAppdropsallincomingandoutgoingtraffic.
Vista de página 27
1 2 ... 23 24 25 26 27 28 29 30 31 32 33 ... 161 162

Comentários a estes Manuais

Sem comentários